> ## Content Index
> Fetch the complete content index at: https://www.chrismessina.me/llms.txt
> Use this file to discover other available public pages before exploring further.

# Another reason to reconsider your password approach
- URL: https://www.chrismessina.me/blog/another-reason-to-reconsider-your-password-approach/
- Published: 2007-01-23T13:23:46.000Z
- Updated: 2026-03-25T03:39:23.000Z
- Author: Chris Messina
- Tags: Digital Identity, Life online, Technology

[According to Finjan Inc.](http://www.finjan.com/Pressrelease.aspx?id=1261&PressLan=1230&lan=3&ref=chrismessina.me), Google's anti-phishing blacklist (used, for example, in their [Firefox extension](http://gemal.dk/blog/2006/03/05/google%5Fsafe%5Fbrowsing%5Fantiphishing%5Fextension%5Fto%5Fland%5Fon%5Ftrun/?ref=chrismessina.me)) [apparently](http://www.techcrunch.com/2007/01/21/google-blacklist-contained-confidential-information/?ref=chrismessina.me) [contained various phished usernames and passwords](http://www.finjan.com/objects/pics/google.jpg?ref=chrismessina.me), suggesting that [you really **should not** use the same username and password combination](http://passpack.wordpress.com/2007/01/23/confirmed-googles-password-leak/?ref=chrismessina.me) across the web. Interestingly, OpenID would have, to some degree, mitigated this breach by moving the username and password combo off by one step, so at worst, the only credentials compromised would have been the publicly known identity provider URL. I'll be posting more about the [OpenID and phishing](http://http//technorati.com/search/OpenI+phishing?ref=chrismessina.me) topic soon, but I think that, in this particular case, the OpenID model would have been slightly more secure in concealing the high value information (namely your username and password credentials), and, better still, in the case of a breach, if you still had access to your account, you'd be able to change your password once and reduce the vulnerability of the remote sites that you use your OpenID to login to. And, note that I'm not talking about the serious matter of spoofing your OpenID provider... in which case OpenID is no better than any other phishable site.

---

### 💬 Comments from the original post

**[motherduce](http://www.motherduce.com/blog?ref=chrismessina.me)** · 2007-02-01 14:39:54

I'm with you on this - I am waiting for the OpenID or something like it to really improve and get some backing to help with all of this. I have 2-3 username/password combos across the web. Any more and I'd forget them.